Circular No. 31/2017/TT-BTTTT stipulates the activities of monitoring the security of information systems.

This Circular stipulates the activities of monitoring the security of information systems nationwide. It applies to agencies, organizations, enterprises, and individuals participating in or related to such monitoring activities. The managers of information systems must carry out monitoring according to requirements, including collecting, analyzing cybersecurity information, and submitting regular reports.

문서 번호31/2017/TT-BTTTT
문서 유형Circular
발행 기관Ministry of Science and Technology
서명자Trương Minh Tuấn — Bộ trưởng
업데이트23. 06. 2026
산업Information and Communications
분야Information Security
발행일15. 11. 2017
발효일15. 01. 2018
효력 만료일
상태In effect
✦ 스마트 요약

This Circular stipulates the activities of monitoring the security of information systems nationwide. It applies to agencies, organizations, enterprises, and individuals participating in or related to such monitoring activities. The managers of information systems must carry out monitoring according to requirements, including collecting, analyzing cybersecurity information, and submitting regular reports.

적용 범위

Agencies, organizations, enterprises, and individuals directly participating in or related to the activities of monitoring the security of information systems nationwide. Particularly, this applies to managers of information systems at level 3 or higher.

핵심 사항

  • Managers of information systems at level 3 or higher must carry out monitoring according to requirements, including collecting and analyzing cybersecurity information.
  • Monitoring activities are carried out through direct or indirect methods. Information system managers may implement monitoring themselves or hire monitoring services.
  • This Circular takes effect from January 15, 2018.
  • Telecommunications enterprises and information technology service providers must cooperate with information system managers in implementing monitoring as required by the Ministry of Information and Communications.
  • The Ministry of Information and Communications monitors information technology systems and services serving the e-Government.

🌐 이 문서의 사회적 영향

  • Positive impact: Enhances protection of cybersecurity, reduces cyber attack risks, and helps organizations and individuals use information systems more effectively.
  • Negative impact: May increase costs for enterprises when implementing monitoring as required by this Circular. Training time is needed to improve monitoring capabilities.

❓ 자주 묻는 질문

What should information system managers do?

Managers of information systems at level 3 or higher must carry out monitoring according to requirements, including collecting and analyzing cybersecurity information. They need to provide full features for collecting and consolidating information, analysis to detect attacks, risks, and cybersecurity incidents.

What should telecommunications enterprises do?

Telecommunications enterprises must cooperate with information system managers in implementing monitoring as required by the Ministry of Information and Communications. They must provide infrastructure, technical, and network system information and offer technical support when necessary.

When does this Circular take effect?

This Circular takes effect from January 15, 2018.

What systems does the Ministry of Information and Communications monitor?

The Ministry of Information and Communications monitors information technology systems and services serving the e-Government. At the same time, it organizes monitoring of important information systems that require priority cybersecurity assurance.

Are there templates for providing information and reporting monitoring activities?

Yes, this Circular provides templates for information provision for monitoring and reporting on monitoring activities by information system managers.

전문

MINISTRY OF INFORMATION AND COMMUNICATION
COMMUNICATION

-------

SOCIALIST REPUBLIC OF VIET NAM
Independence - Freedom - Happiness
---------------

Number: 31/2017/TT-BTTTT

Hanoidated November 15 of the Government stipulating the functions, tasks, powers, and organizational structure of the Ministry of Industry and Trade; 2017

CIRCULAR

Regarding the operation of information system security monitoring

||| Pursuant to the Cybersecurity Law dated November 19, 2015;

Pursuant to Decree No. 72/2013/NĐ-CP dated July 15, 2013 of the Government on managing, providing, and using Internet services and information on networks;

Pursuant to Decree No. 25/2014/NĐ-CP dated April 7, 2014 of the Government on crime prevention and other violations of law using high technology;concerning crimes and other violations of law using advanced technology; to ensure national cybersecurity;

Pursuant to Decree No. 85/2016/NĐ-CP dated July 1, 2016 of the Government on ensuring information security according to levels;

Pursuant to Decree No. 17/2017/NĐ-CP dated February 17, 2017, issued by the Government, on the functions, tasks, powers, and organizational structure of the Ministry of Information and Communications;

Pursuant to Decision No. 05/2017/QĐ-TTg dated March 16, 2017 of the Prime Minister promulgating regulations on the system of emergency response plans for national information security protection;1.6. Internet Protocol (IP) addresses used in the information system:1.7. Network infrastructure equipment serving the information system:□ Switch

Implementing Resolution No. 36a/NQ-CP dated October 14, 2015 of the Government on the National Program on Information Technology Development;Government online;

At the proposal of the Director of the Vietnam Computer Emergency Response Team;

The Minister of Information and Communications issues this Circular on the operation of information system security monitoring.

PART I

GENERAL PROVISIONS

Article 1. Scope of Regulation

This Circular stipulates the operation of information system security monitoring (hereinafter referred to as monitoring) throughout the country, excluding information systems managed by the Ministry of National Defense and the Ministry of Public Security.

Article 2. Applicability

This Circular applies to agencies, organizations, enterprises, and individuals directly participating in or related to monitoring activities nationwide.

Chapter II

INFORMATION SYSTEM SECURITY MONITORING

Article 3. Principles of Monitoring

1. Ensuring continuous and regular implementation.

2. Proactively observing, analyzing, and preventing to promptly detect and prevent risks and information security incidents.

3. Ensuring stable and confidential operations for information exchanged during the monitoring process.

4. Coordinating closely and effectively between the monitoring activities of the Ministry of Information and Communications and those of the information system managers; gradually building the capability for interconnection between the monitoring system of the Ministry of Information and Communications and the monitoring system of information system managers nationwide.

Article 4. Methods of Monitoring

1. Monitoring can be conducted through direct or indirect methods. Information system managers may implement directly or hire services for monitoring. In necessary cases, based on their capacity, situation, and actual resources, information system managers may request relevant units under the Ministry of Information and Communications to provide appropriate support for monitoring in accordance with actual resources.

2. Direct monitoring involves conducting monitoring by placing devices capable of analyzing data streams (surveillance), directly collecting information from log files, and warning systems being monitored to detect signs of attacks, risks, and information security incidents. Direct monitoring includes the following activities:

a) Analyzing and collecting information on information security:

- Analyzing and surveilling information security on network paths/data flows at Internet connection ports using tools capable of analyzing network paths to detect attacks, risks, and information security incidents such as suitable attack detection/prevention devices (e.g., IDS/IPS/Web Firewall, etc.);

- Collecting log files, warnings reflecting the activities of applications, information systems, and security devices.

b) Consolidating, synchronizing, verifying, and processing information on information security to detect attacks, risks, and information security incidents or eliminate inaccurate information.

3. Indirect monitoring involves implementing techniques to collect information from related sources; inspecting and reviewing the objects to be monitored to assess operational status, responsiveness, and combining with other related factors to analyze and detect attacks, risks, and information security incidents. Indirect monitoring includes the following activities:

a) Collecting, analyzing, and verifying information about attacks, risks, and information security incidents related to the monitored objects from related sources;

b) Remotely or directly inspecting and reviewing the monitored objects to evaluate the status, detect potential attacks, risks, and information security incidents that could be exploited or cause harm.

Article 5. Direct supervision requirements for information system managers

Information system managers have the responsibility to proactively implement supervision in accordance with current regulations. For information systems at level 3 or higher, the supervision activities of the information system manager must meet the following minimum requirements:

1. The central monitoring component of the information system manager must meet the following requirements:

a) Provide all necessary features for collecting and consolidating network security information;

b) Analyze collected information to detect and warn against attacks, risks, and network security incidents that could affect the system's operations or service provision capabilities;

c) Provide an interface convenient for continuous monitoring by supervisory staff;

d) Conduct collection and analysis of the following minimum input information: web server logs (web server) with web applications (for example: electronic portal, online public services, etc.); alerts/logs from base monitoring devices; alerts/logs from firewalls set up to protect Internet connection flows related to monitored objects;

e) The processing capacity of the central monitoring component of the information system manager must be appropriate for the volume, format, and capable of analyzing network security information collected from monitored systems.

2. Network security information collection and base monitoring must meet the following requirements:

a) Collect network security information from logs and alerts of software/devices related to monitored objects to provide to the central monitoring component of the information system manager or as required by competent authorities under the Ministry of Information and Communications. Minimum network security information to collect and provide includes: web server logs of web applications (for example: electronic portal, online public services, etc.); alerts/logs from base monitoring devices; alerts/logs from firewalls set up to protect Internet connection flows related to monitored objects;

b) Base monitoring devices must ensure functions for detecting attacks, risks, and network security incidents; they need to be configured to ensure comprehensive monitoring coverage of all Internet connection paths of monitored objects;

c) Monitoring devices must meet the minimum functions of detection, creation of attack detection rules based on information such as: source IP address, destination IP address, source port address, destination port address, special data segments in transmitted packets. For state agencies and organizations implementing base monitoring devices themselves, priority should be given to using existing attack detection devices (for example: IDS, IPS, Web firewall, etc.) to serve as base monitoring devices;

d) For information systems serving E-Government using encrypted protocols (for example: https), technical solutions must be established to ensure that network security monitoring devices can obtain full information to detect attacks, risks, and network security incidents;

e) Establish and connect base monitoring devices to the monitoring system of the Ministry of Information and Communications according to guidance and requirements of competent authorities.

3. Supervision implementation content:

a) Continuously monitor, establish daily reports, ensuring the information system manager's monitoring system operates stably and continuously, collecting information steadily and continuously;

b) Develop and issue network security monitoring regulations, specifying details about periodic statistics on handling results and report preparation;

c) Monitor and operate base monitoring devices to ensure stability and continuity, making timely adjustments when changes occur, and fully implementing guidance from the Ministry of Information and Communications to ensure effective monitoring;

d) Prepare weekly supervision result reports to inform the information system manager, including the following complete information: monitoring time; list of attacked targets requiring attention (IP addresses, service descriptions, attack times); detected attack techniques and related evidence; attackers; changes in the monitored system and the monitoring system; etc.;

đ) Classify threats, risks, and network security incidents according to specific circumstances;

e) Periodically compile statistics on threat, risk, and network security incident handling results to support storage and reporting work;

g) In cases where the information system manager requests functional units of the Ministry of Information and Communications to perform base monitoring or systems within the Ministry's monitoring responsibility, the information system manager has the responsibility to provide and update information about the system to be monitored and describe the technical deployment plan of the information system manager's monitoring system to the Ministry of Information and Communications according to the information provision form in Appendix 1, which includes the following information:

- Description of the monitored object, including basic information such as: IP address, domain name, provided service, operating system name and version, web application software;

- Location of the information system manager's monitoring system, bandwidth of connections to the monitored object, expected information to be collected and collection protocols, for example IDS alerts, firewall logs (log firewall), web server logs (log web server), etc.

h) Minimum monitoring information storage capacity must reach an average of 30 days of normal operation;

i) Provide periodic or ad hoc monitoring information as required by the Ministry of Information and Communications in accordance with the law;

k) Report on the information system manager's monitoring activities every six months according to the form in Appendix 2.

Article 6. Supervisory Activities of Enterprises

Telecommunication enterprises, information technology service providers, and network security service providers shall be responsible for:

1. Cooperating with system administrators in supervisory activities upon request from the Ministry of Information and Communications.

2. Providing technical and infrastructure information about networks and implementing technical support as requested by the Ministry of Information and Communications to facilitate its supervisory activities.

3. Implementing supervisory tasks as stipulated in Article 7 of Decision No. 05/2017/QĐ-TTg issued by the Prime Minister.

Article 7. Supervisory Contact Points

1. System administrators shall be responsible for appointing individuals or departments as supervisory contact points for cybersecurity to coordinate with functional units of the Ministry of Information and Communications.

2. Supervisory contact points must ensure timely and continuous provision and reception of information. They have the function of conducting supervisory activities within their own information systems.

3. Supervisory contact points shall implement the provision and exchange of information through one or multiple methods such as letters, emails, phone calls, faxes, or specialized communication software to ensure confidentiality.

4. Information on supervisory contact points includes: individual name, department name, position, address, telephone number (landline and mobile), email address, digital signature (if available).

Article 8. Exchange, Provision, and Sharing of Information

1. Encouraging supervisory contact points to exchange and provide information to each other for the purpose of coordinating in monitoring, warning, responding to incidents, and enhancing proactive measures against threats and attack methods targeting organizational and individual cybersecurity.

2. Shared, provided, and exchanged information includes details on cyber attacks, risks, incidents; attack methods, origins, impacts; management and technical measures to handle and mitigate incidents.

3. Principles for exchanging and providing information

a) Timely, accurate, and appropriate application of management and technical measures to secure exchanged information;

b) Proactively verifying exchanged information to ensure its authenticity;

c) Using one or multiple forms of information exchange such as websites, letters, emails, messages, phone calls, faxes;

d) When providing and exchanging information with functional units of the Ministry of Information and Communications, it must be done according to the Ministry's guidelines.

Article 9. Activities to Enhance Supervisory Capabilities

1. Organizing regular meetings and seminars on supervisory activities.

2. Training, practicing, and simulating to enhance supervisory capabilities.

3. Urging and inspecting the implementation of supervisory and warning activities by specialized departments for cybersecurity.

4. Sharing knowledge and experience in supervision, warning, and incident response.

5. Researching and developing tools to support cooperative information exchange in supervisory, warning, and incident response work.

6. Developing specialized products and services for monitoring, analysis, and warnings tailored to specific supervisory targets.

7. Promoting the establishment of bilateral and multilateral cooperation agreements among specialized departments for cybersecurity to enhance supervisory and warning capabilities.

8. Strengthening international cooperation in supervisory, warning, and incident response activities.

Chapter III

SUPERVISORY ACTIVITIES OF THE MINISTRY OF INFORMATION AND COMMUNICATIONS

Article 10. The Ministry of Information and Communications' Monitoring Model

1. Central monitoring activities:

a) Refers to the collection, tracking, detection, analysis, processing, reporting, and evidence gathering on signs of attacks, risks, and cybersecurity incidents based on cybersecurity data/information collected through direct monitoring via observation systems or indirect monitoring, while storing collected data in event form and centrally managing observation systems.

b) Are carried out through the Vietnam Cyber Incident Monitoring System and the Vietnam Internet Attack Handling System managed and operated by competent units of the Ministry of Information and Communications on the principle of data sharing and coordinated operations to enhance monitoring effectiveness.

2. Observation Systems

a) Consist of devices and software capable of monitoring, collecting, analyzing, and providing log information, status, and alerts for central monitoring activities to serve the analysis and detection of cybersecurity incidents, weaknesses, threats, and vulnerabilities.

b) Are provided with appropriate technical conditions and placement locations for operation and data collection from monitored objects according to guidelines issued by competent units of the Ministry of Information and Communications.

c) Are established, managed, and operated by competent units of the Ministry of Information and Communications in collaboration with system administrators in accordance with legal regulations.

d) Devices/software implementing basic observations are set up to connect and serve central monitoring activities based on technical standards, specifications, or operational guidelines of the Ministry of Information and Communications.

Article 11. Monitoring Activities of the Ministry of Information and Communications

1. The Ministry of Information and Communications conducts monitoring of systems and services supporting the electronic government.

2. Upon request from system administrators, the Ministry of Information and Communications organizes monitoring of important systems requiring priority cybersecurity assurance in line with available resources.

3. Central monitoring activities of the Ministry of Information and Communications ensure the capability to receive, analyze monitoring information collected from basic observation systems and equipment/systems serving indirect monitoring.

4. Monitoring activities of the Ministry of Information and Communications include:

a) Selecting, managing, and updating the list of monitored entities as stipulated in this Circular and related legal documents.

b) Tracking, operating the central monitoring center, preparing analytical monitoring reports; inspecting and urging monitoring and surveillance work.

c) Compiling, storing, analyzing, and classifying information and data collected from basic observation systems, equipment/systems serving indirect monitoring, and other information sources.

d) Conducting checks and analyses of evidence and data to detect unusual signs, cybersecurity risks. In cases where risks or incidents have not been clearly verified, additional measures are taken to gather necessary information and data to increase the accuracy of analysis results and warning information.

đ) Conducting investigations and verifications to determine risks and incidents affecting monitored entities. Analyzing and categorizing cyberattacks, risks, and cybersecurity incidents based on specific circumstances. Warning cybersecurity departments, system operators, and system administrators when attacks, risks, or incidents occur against monitored entities.

e) Guiding system administrators in implementing monitoring; organizing and guiding connections from system administrators' monitoring systems to central monitoring systems of the Ministry of Information and Communications. Ensuring the security of cybersecurity data during collection and analysis.

g) Regularly compiling monitoring results, warning situations, and handling of cyberattacks, risks, and cybersecurity incidents for archival and reporting purposes.

h) Guiding and supporting system operators and system administrators to implement emergency response and handling of cyberattacks, risks, and cybersecurity incidents when necessary.

i) Assisting some system operators and system administrators in establishing suitable basic observation systems based on available resources.

k) Competent units of the Ministry of Information and Communications annually prepare budgets and approve, allocate funds for monitoring tasks from state budget and other lawful sources in accordance with legal provisions and guidance from competent authorities for approval by the Minister or authorized authority.

Chapter IV

RESPONSIBILITIES OF ORGANIZATIONS AND ORGANIZATIONS

Article 12. The Cybersecurity Center

1. Manage and operate the Vietnam Internet Attack Handling System to carry out central monitoring activities.

2. Compile monitoring results and information, data on cybersecurity for state management work on cybersecurity.

3. Urge the implementation of basic requirements for ensuring information system security and monitoring according to the levels prescribed by laws on information system security.

4. Take the lead and coordinate with the VNCERT Center to research and develop technical criteria and detailed guidelines for connecting between the Basic Monitoring System and the Vietnam Internet Attack Handling System to be issued by the Minister of Information and Communications.

5. Coordinate or take the lead in monitoring information systems in important fields that require priority cybersecurity assurance upon request from the system managers.

Article 13. The VNCERT Center

1. Manage and operate the Network Security Incident Monitoring System to carry out central monitoring activities.

2. Compile monitoring results and information, data on cybersecurity for coordination and incident response work.

3. Take the lead and coordinate with the Cybersecurity Center to develop monitoring procedures; organize the implementation of activities to enhance monitoring capabilities; urge, follow up, and inspect network security monitoring and warning activities according to the division of labor by the Minister of Information and Communications.

4. Take the lead and coordinate with the Cybersecurity Center to research and develop technical criteria and detailed guidelines for connecting between the Basic Monitoring System and the Network Security Incident Monitoring System to be issued by the Minister of Information and Communications.

5. Take the lead in monitoring and warning cybersecurity for information systems and technology services serving e-Government. Coordinate or take the lead in monitoring information systems in important fields that require priority cybersecurity assurance upon request from the system managers.

6. Compile and report national cybersecurity monitoring and warning results and statistics on cyber attacks, risks, and incidents.

Article 14. Managers of Information Systems

1. Direct the monitoring of information systems under their management, and cooperate with competent units of the Ministry of Information and Communications to implement monitoring according to regulations.

2. Implement guidelines and closely cooperate with competent units of the Ministry of Information and Communications in monitoring activities.

3. Provide information on monitoring activities according to the requirements of the Ministry of Information and Communications.

4. Report monitoring results regularly every six months according to the form at Appendix 2 or when requested by the Ministry of Information and Communications.

5. Prepare connection ports and backup interface connections at Internet access points according to specified technical criteria to establish monitoring points of the Ministry of Information and Communications when necessary.

6. Managers of information systems monitored by the Ministry of Information and Communications shall be responsible for:

a) Identify and list information systems and objects requiring monitoring, and provide related technical information of these systems and objects to the Ministry of Information and Communications;

b) Implement the monitoring system of the information system manager according to this Circular and relevant laws; cooperate in providing information about infrastructure and information systems to be monitored and perform technical support according to the requirements of competent units of the Ministry of Information and Communications;

c) Organize a team to receive warnings and handle cyber attacks, risks, and incidents according to warnings and requests from competent units of the Ministry of Information and Communications;

d) Regularly compile statistics on handling cyber attacks, risks, and incidents for record-keeping and reporting purposes.

7. Annually prepare and approve, allocate budget funds for monitoring tasks from the state budget and other lawful sources according to legal provisions and guidance from competent authorities.

Chapter V

IMPLEMENTATION

Article 15. Effective Date

1. This Circular takes effect from January 15, 2018.

2. During implementation, if there are difficulties or new issues, organizations and individuals concerned should promptly reflect them to the Ministry of Information and Communications for guidance or consideration for supplementation and amendment.

Place of Receipt:
- Prime Minister, Deputy Prime Ministers;
- Government Office;
- Central Party Office and Party Committees;
- General Secretary's Office;
- National Assembly's Office;
- President's Office;
- Ministries, agencies equivalent to ministries, and government agencies;
- Supreme People's Court;
- Supreme People's Procuracy;
- State Audit Agency;
- Provincial People's Councils and People's Committees under central jurisdiction;
- Central Agencies of Mass Organizations;
- National Steering Committee for Information Technology Application;
- National Steering Committee on Cybersecurity;
- Specialized units on IT and cybersecurity of Ministries, agencies equivalent to ministries, and government agencies;
- Provincial Departments of Information and Communications;
- Telecommunications and Internet service companies;
- Official Gazette, Government Portal;
- Legal Documents Supervision Bureau (Ministry of Justice);
- Ministry of Information and Communications: Ministers, Deputy Ministers, units under the Ministry, Ministry Portal;
- To be filed: VT, VNCERT (250)
THE MINISTER
(Signed)

TRUONG MINH TUN

 

 

Appendix 1: Information Provision Form for Monitoring

SUPERIOR UNIT
NAME OF ENTITY
-------

SOCIALIST REPUBLIC OF VIET NAM
Independence - Freedom - Happiness
---------------

 

………….Date... Month... Year 20...

 

INFORMATION PROVISION FORMFOR DAILY REPORTINGON CYBERSECURITY MONITORINGOF INFORMATION SYSTEMS
THE I. Information on the operating unit and information provider contact

- Name of agency/unit managing and operating the information system: ...

- Based on the Law on Information Technology dated June 29, 2006;

- Name of information provider/contact: ...

- Position: ...

- Address: ...

- Phone number: ...

II. Information systems to be monitored

A. Existing information systems:

- Email: …

□ Electronic portal: ...

□ Online public service system: ...

□ Email system: ...

□ Administrative document management system: ...

□ Database system: ...

□ Other systems

(specify)

B. Specific information on information systems to be monitored 1. First information system:õ): ..................................................................................................................

1.1. Name of information system: ...

1.2. Brief description of functions, scale, and scope of service of the information system: ...

1.3. Level of the information system: ...

1.4. Location of the information system: ...

..................................................................................................................

□ Data center of the agency/unit, located at: ...

managed by

(name of the unit managing and operating the data center):

□ Renting hosting outside, at the data center of (name of the unit providing hosting and data center services) ...................................

(location of the data center) 1.5. Domain name, URL of the information system: ...of the Government stipulating functions, tasks, powers, and organizational structure of the Ministry of Home Affairs1.6. Internet IP addresses used in the information system::   

in 1.7. Network infrastructure equipment serving the information system:无效 □ Switch(type, model): ..............................................................................................

□ Router

(type, model)

.............................................................................................................................................

□ Router

(type, model) Third-party technique: (Technical description similar to the first attack technique): ..............................................................................................

3.4. Fourth attack technique: (Technical description similar to the first attack technique) Third-party technique: (Technical description similar to the first attack technique): ..............................................................................................

□ IDS/IPS (Intrusion Detection/Prevention Systems) Third-party technique: (Technical description similar to the first attack technique): ............................

□ Firewall (specify type, model)Deputy ministers of ministerial-level agencies,3.5. Fifth attack technique:: .........................................................................

□ Other network devices Third-party technique: (Technical description similar to the first attack technique): ..........................................................................

1.8. Platform software, system software, tools (PMNT), operating systems (OS) used in the information system

□ Server OS: …

□ Application PMNT: …

□ Workstation OS: …

□ Other platform, system software, tools, OS (specify clearly): ......................

1.9. Other technical information about the information system (specify clearly):

..................................................................................................................

1.10. Information security monitoring solutions for the information system:

□ Available (specify the following information clearly)    □ Not available

a. Monitoring by the system owner:

□ Self-execution.

□ Service outsourcing (specify the service provider): ................................................................

- Monitoring method (direct or indirect): ....................................................................

- Description of monitoring technology and techniques: …

..................................................................................................................

- Event processing rate (EPS) capability: …EPS.

- Storage capacity for network security events per day (GB/day): …GB/Day.

- Does the monitoring system use correlation rule engines: □ Yes; □ No.

- Level of monitoring (Select from the levels below)billion □ Basic level monitoring (network and perimeter): monitor network devices such as routers, switches, firewalls (Firewall), IDS/IPS.□ Operating system level monitoring: collect and analyze OS logs.:

□ Application level monitoring: collect, analyze, and monitor application service logs (e.g., web server; mail server, etc.).

□ Database level monitoring: collect, analyze, and monitor database service logs.

- Components of the monitoring system

(Select from the components below)

□ Base observation component (such as sensors collecting information, IDS/IPS devices, firewall devices, etc.) □ Data collection/standardization component (Connector):

□ Monitoring data storage component (Logger)

□ Central analysis and monitoring component (ESM)

- Description of base observation components: …

b. Other monitoring solutions

(if applicable, specify the implementing unit, briefly describe the monitoring technology and techniques)

..................................................................................................................

..................................................................................................................

c. Information security monitoring by the Ministry of Information and Communications for the information system: - Request the Ministry of Information and Communications to::

...........................................................................................................................................

..................................................................................................................

..................................................................................................................

□ Deploy connection monitoring;

□ Not request implementation;

□ Other …

- Request support for direct/indirect monitoring by the system owner:

(specify clearly whether direct, indirect, or both)

- Other Requests/Proposals: …

□ Yes 2. Second information system:: ...................................

□ No

(specify as for the first information system)

..................................................................................................................

n. nth information system: III. Human resources for information security monitoring (monitoring)

..................................................................................................................

1. Unit leader directing monitoring work III. Human resources for information security monitoring (monitoring)

..................................................................................................................

(specify full name, position, phone number, email)

2. Head of the monitoring department 3. List of monitoring staff of the unit::......

.................................................................................................................................................................................................................................

(professional qualifications) 3. List of monitoring staff of the unit::..........

..................................................................................................................

..................................................................................................................

Certificates

No.

Full Name

Training related technical and vocational skills

4. Recommendations of the unit regarding monitoring work:… Person filling out the form - Column (7): Land area in land allocation decisions, lease decisions, or documents of the competent authority or actual land area managed and used (applicable to assets that are buildings and land).

 

 

 

 

 

 

 

 

(Signature, full name, phone number, email)

..................................................................................................................

Appendix 2: Template for reporting on monitoring activities of the system owner
year …..
Head of the unit
(Signature, stamp)

 PERIODIC REPORT OF THE SYSTEM OWNER

SUPERIOR UNIT
NAME OF ENTITY
-------

SOCIALIST REPUBLIC OF VIET NAM
Independence - Freedom - Happiness
---------------

 

………….Date... Month... (from date ………

 

REPORT

I. Summary of Monitoring Information- Monitoring period:... hours... minutes on ... to ... hours ... minutes on ...

- Total number of collected information security events:APPLICATION FOR RESIDENCE OUTSIDE )

- Based on the Law on Information Technology dated June 29, 2006;

- Total number of high-risk information security events:

- Information security status: [Severe/Dangerous/Normal/Safe]

- Number of incidents occurred:

- Summary of information security situation during the monitoring period:

II. Monitoring Results

1. List of most frequently detected attack techniques (at least five most frequent attack techniques)

Attack technique

..................................................................................................................

..................................................................................................................

Number of attacks

2. List of most frequently attacked services (at least five most frequently attacked services)

Serial number

Service port/IP address

3. List of most frequently attacked IP addresses (at least five IP addresses)

1

 

 

2

 

 

3

 

 

4

 

 

5

 

 

IP address

Serial number

Description of device/software with attacked IP address

Services

3. List of most frequently attacked IP addresses (at least five IP addresses)

1

 

 

 

2

 

 

 

3

 

 

 

4

 

 

 

5

 

 

 

- Services provided:

Serial number

1. Service name:

+ Service port number:

3. List of most frequently attacked IP addresses (at least five IP addresses)

1

 

+ Protocol used:

+ Software, version providing service:

+ Time

2. Service name: …

4. List of top source IP addresses attacking from within the country (at least five IP addresses)

5. List of top source IP addresses attacking from abroad (at least five IP addresses)

III. Typical Attacks

 

2

 

 

 

3

 

 

 

4

 

 

 

5

 

 

 

1. Most dangerous types of attacks (at least five):

Serial number

1. Service name:

3. List of most frequently attacked IP addresses (at least five IP addresses)

1

 

 

2

 

 

3

 

 

4

 

 

5

 

 

. Attack technique 1

Serial number

1. Service name:

3. List of most frequently attacked IP addresses (at least five IP addresses)

1

 

 

2

 

 

3

 

 

4

 

 

5

 

 

- Name of attack technique: …

- International code (if any): …

1. 1- Targeted objects: …- Indicators: …:

- Description: …

- Quantity and time of occurrence: …

- Severity assessment: …

- Impact: …

- Implemented response measures: …

- Reference materials: …

- Additional notes: …

1.2. Attack technique 2: (Description similar to attack technique 1)

1.3. Attack technique 3: (Description similar to attack technique 1)

1.4. Attack technique 4: (Description similar to attack technique 1)

1.5. Attack technique 5: (Description similar to attack technique 1

.n. Attack technique n: …

2. Most frequently occurring types of attacks (at least five)2.1. Attack technique 1- Indicators: …)

2.2. Attack technique 2: (Description similar to attack technique 1

2.3. Attack technique 3: (Description similar to attack technique 1)

.............................................................................................................................................

12.4. Attack technique 4: (Description similar to attack technique 1)

2.5. Attack technique 5: (Description similar to attack technique 1

2.n. Attack technique n::

- Description: …

- Quantity and time of occurrence: …

- Severity assessment: …

- Impact: …

- Implemented response measures: …

- Reference materials: …

- Additional notes: …

1.2. Attack technique 2: (Description similar to attack technique 1)

1.3. Attack technique 3: (Description similar to attack technique 1)

1.4. Attack technique 4: (Description similar to attack technique 1)

1.5. Attack technique 5: (Description similar to attack technique 1

3. Newly emerging types of attacks (at least five)3.1. Attack technique 1)

3.2. Attack technique 2: (Description similar to attack technique 1))

3.3. Attack technique 3: (Description similar to attack technique 1) 3.4. Attack technique 4: (Description similar to attack technique 1)

3.5. Attack technique 5: (Description similar to attack technique 1)

...........................................................................................................................................

3.n. Attack technique n: ...................................................................................................

IV. Other Information Security Issues During the Monitoring Period

V. Recommendations and Suggestions::

- Description: …

- Quantity and time of occurrence: …

- Severity assessment: …

- Impact: …

- Implemented response measures: …

- Reference materials: …

- Additional notes: …

1.2. Attack technique 2: (Description similar to attack technique 1)

1.3. Attack technique 3: (Description similar to attack technique 1)

1.4. Attack technique 4: (Description similar to attack technique 1)

1.5. Attack technique 5: (Description similar to attack technique 1

- National Cybersecurity Center (VNCERT);

- Cybersecurity Department;(Technical description similar to the first attack technique)

3.n. Attack technique n:

IV. Other issues related to information security during the monitoring period V. Recommendations and suggestions:)

...........................................................................................................................................

- Vietnam National Cybersecurity Incident Response Team (VNCERT);Cybersecurity Bureau; ...................................................................................................

IV. Other issues concerning information security during the monitoring period

...........................................................................................................................................

...........................................................................................................................................

...........................................................................................................................................

V. Recommendations and suggestions:

...........................................................................................................................................

...........................................................................................................................................

Place of Receipt:
- As above;
- VNCERT Center;
-
Information Security Bureau;
- File...

Head of the unit
(sign, stamp)

 

 

 

원본 문서(PDF)

새 탭에서 PDF 열기 ↗

관계도

↑ 근거 및 이 문서에 영향을 주는 문서
근거 34
72/2013/NĐ-CP Nghị định số 72/2013/NĐ-CP Quản lý, cung cấp, sử dụng dịch vụ internet và thông tin trên mạng 만료됨 85/2016/NĐ-CP Nghị định số 85/2016/NĐ-CP Về bảo đảm an toàn hệ thống thông tin theo cấp độ 발효 중 17/2017/NĐ-CP Nghị định số 17/2017/NĐ-CP Quy định chức năng, nhiệm vụ, quyền hạn và cơ cấu tổ chức của Bộ Thông tin và Truyền thông 만료됨 25/2014/NĐ-CP Nghị định số 25/2014/NĐ-CP Quy định về phòng, chống tội phạm và vi phạm pháp luật khác có sử dụng công nghệ cao 발효 중 86/2015/QH13 Luật An toàn thông tin mạng số 86/2015/QH13 발효 중 173/2025/QĐ-UBND Quyết định số 173/2025/QĐ-UBND Ban hành Quy chế quản lý, khai thác và vận hành Trung tâm Dữ liệu tỉnh Ninh Bình 발효 중 89/2024/QĐ-UBND Quyết định số 89/2024/QĐ-UBND Ban hành Quy chế bảo đảm an toàn thông tin mạng tỉnh Hà Nam 발효 중 73/2024/QĐ-UBND Quyết định số 73/2024/QĐ-UBND Sửa đổi, bổ sung một số điều của Quy chế bảo đảm an toàn thông tin mạng trong hoạt động ứng dụng công nghệ thông tin của cơ quan nhà nước trên địa bàn tỉnh Thái Nguyên ban hành kèm theo Quyết định số 10/2020/QĐ-UBND ngày 08 tháng 5 năm 2020 của Ủy ban nhân dân tỉnh Thái Nguyên 만료됨 29/2026/QĐ-UBND Quyết định số 29/2026/QĐ-UBND Ban hành định mức kinh tế - kỹ thuật giám sát đảm bảo an toàn thông tin đối với hệ thống hạ tầng kỹ thuật dịch vụ công nghệ thông tin phục vụ công tác quản lý nhà nước lĩnh vực tài nguyên, môi trường 발효 중 02/2026/QĐ-UBND Quyết định số 02/2026/QĐ-UBND Ban hành Quy chế bảo đảm an toàn thông tin, an ninh mạng trong hoạt động ứng dụng công nghệ thông tin của các cơ quan nhà nước trên địa bàn tỉnh Gia Lai 발효 중 59/2025/QĐ-UBND Quyết định số 59/2025/QĐ-UBND Ban hành Quy chế quản lý, vận hành, khai thác và đảm bảo an toàn thông tin đối với Trung tâm Tích hợp dữ liệu tỉnh Bắc Ninh 발효 중 10/2025/QĐ-UBND Quyết định số 10/2025/QĐ-UBND Ban hành Quy chế bảo đảm an toàn thông tin, an ninh mạng trong hoạt động ứng dụng công nghệ thông tin của các cơ quan nhà nước trên địa bàn tỉnh Phú Yên 만료됨 3/2025/QĐ-UBND Quyết định số 3/2025/QĐ-UBND Ban hành Quy chế quản lý, vận hành, khai thác và đảm bảo an toàn thông tin đối với Trung tâm Tích hợp̣ dữ liệu tỉnh Bắc Giang 발효 중 39/2024/QĐ-UBND Quyết định số 39/2024/QĐ-UBND Ban hành Quy chế bảo đảm an toàn thông tin mạng trong hoạt động ứng dụng công nghệ thông tin của các cơ quan nhà nước trên địa bàn tỉnh Hải Dương 발효 중 38/2024/QĐ-UBND Quyết định số 38/2024/QĐ-UBND Ban hành Quy chế Quản lý, vận hành và khai thác Trung tâm Tích hợp dữ liệu tỉnh Hòa Bình 발효 중 48/2024/QĐ-UBND Quyết định số 48/2024/QĐ-UBND Ban hành Quy chế bảo đảm an toàn thông tin mạng tỉnh Ninh Bình 발효 중 36/2023/QĐ-UBND Quyết định số 36/2023/QĐ-UBND Ban hành Quy chế bảo đảm an toàn thông tin mạng cho các hệ thống thông tin cấp độ 3 tại Trung tâm tích hợp dữ liệu tỉnh 발효 중 33/2023/QĐ-UBND Quyết định số 33/2023/QĐ-UBND Ban hành Quy chế bảo đảm an toàn thông tin mạng trong hoạt động ứng dụng công nghệ thông tin của cơ quan nhà nước tỉnh Vĩnh Phúc 만료됨 11/2023/QĐ-UBND Quyết định số 11/2023/QĐ-UBND Ban hành Quy chế quản trị, quản lý, vận hành, khai thác hệ thống hạ tầng, ứng dụng, cơ sở dữ liệu dùng chung tại Trung tâm tích hợp dữ liệu tỉnh Bắc Kạn 만료됨 07/2022/QĐ-UBND Quyết định số 07/2022/QĐ-UBND Ban hành Quy chế quản lý, khai thác và vận hành Trung tâm Dữ liệu tỉnh Ninh Bình 만료됨 55/2021/QĐ-UBND Quyết định số 55/2021/QĐ-UBND Ban hành Quy chế quản lý, vận hành và khai thác Trung tâm dữ liệu tỉnh Long An 만료됨 29/2021/QĐ-UBND Quyết định số 29/2021/QĐ-UBND Ban hành Quy chế bảo đảm an toàn thông tin mạng trong hoạt động ứng dụng công nghệ thông tin trên địa bàn tỉnh Tây Ninh 발효 중 17/2021/QĐ-UBND Quyết định số 17/2021/QĐ-UBND Ban hành Quy chế quản lý, vận hành và khai thác Trung tâm dữ liệu tỉnh Cao Bằng 발효 중 26/2018/QĐ-UBND Quyết định số 26/2018/QĐ-UBND Ban hành quy chế quản lý, khai thác và vận hành Trung tâm tích hợp dữ liệu tỉnh Quảng Ninh 발효 중 76/2024/QĐ-UBND Quyết định số 76/2024/QĐ-UBND Ban hành Quy chế về bảo đảm an toàn thông tin mạng trong hoạt động ứng dụng công nghệ thông tin của các cơ quan Nhà nước trên địa bàn tỉnh Ninh Thuận 발효 중 34/2022/QĐ-UBND Quyết định số 34/2022/QĐ-UBND ban hành Quy chế quản lý, vận hành Trung tâm Giám sát an toàn không gian mạng tỉnh Yên Bái 발효 중 11/2022/QĐ-UBND Quyết định số 11/2022/QĐ-UBND Ban hành Quy chế quản lý, vận hành, khai thác và sử dụng trung tâm tích hợp dữ liệu tỉnh Yên Bái 발효 중 61/2021/QĐ-UBND Quyết định số 61/2021/QĐ-UBND Ban hành Quy chế bảo đảm an toàn thông tin mạng trong hoạt động ứng dụng công nghệ thông tin trong các cơ quan nhà nước trên địa bàn tỉnh Lào Cai 발효 중 35/2021/QĐ-UBND Quyết định số 35/2021/QĐ-UBND Ban hành Quy chế bảo đảm an toàn thông tin trong hoạt động ứng dụng công nghệ thông tin của các cơ quan nhà nước trên địa bàn tỉnh cao Bằng 발효 중 15/2021/QĐ-UBND Quyết định số 15/2021/QĐ-UBND Ban hành Quy chế quản lý, vận hành và khai thác sử dụng Hệ thống Trung tâm Dữ liệu thành phố Hải Phòng 발효 중 03/2021/QĐ-UBND Quyết định số 03/2021/QĐ-UBND Ban hành Quy chế quản lý, vận hành, sử dụng trung tâm dữ liệu tỉnh Bạc Liêu 만료됨 28/2020/QĐ-UBND Quyết định số 28/2020/QĐ-UBND Ban hành Quy chế quản lý, vận hành và khai thác Trung tâm Dữ liệu tỉnh Thái Nguyên 발효 중 50/2024/QĐ-UBND Quyết định số 50/2024/QĐ-UBND Ban hành Quy chế quản lý, vận hành, sử dụng Trung tâm dữ liệu tỉnh Bạc Liêu 만료됨
31/2017/TT-BTTTT
Circular No. 31/2017/TT-BTTTT stipulates the activities of monitoring the security of information systems.
In effect
↓ 이 문서의 영향을 받는 문서
관련 27
11/2022/QĐ-UBND Quyết định số 11/2022/QĐ-UBND Ban hành Quy chế về tổ chức và hoạt động của Phòng Kinh tế thuộc Ủy ban nhân dân huyện Nhà Bè 만료됨 3/2025/QĐ-UBND Quyết định số 3/2025/QĐ-UBND Quy định chức năng, nhiệm vụ, quyền hạn và cơ cấu tổ chức của Sở Công Thương tỉnh Phú Thọ 발효 중 15/2021/QĐ-UBND Quyết định số 15/2021/QĐ-UBND Ban hành Quy định một số nội dung bồi thường, hỗ trợ về nhà ở, công trình kiến trúc gắn liền với đất khi Nhà nước thu hồi đất trên địa bàn tỉnh Lào Cai 만료됨 61/2021/QĐ-UBND Quyết định số 61/2021/QĐ-UBND Ban hành Quy định chi tiết một số điều về bồi thường, hỗ trợ, tái định cư khi Nhà nước thu hồi đất trên địa bàn tỉnh Vĩnh Phúc 만료됨 34/2022/QĐ-UBND QUYẾT ĐỊNH SỐ 34/2022/QĐ-UBND QUY ĐỊNH CHỨC NĂNG, NHIỆM VỤ, QUYỀN HẠN VÀ CƠ CẤU TỔ CHỨC CỦA THANH TRA TỈNH NGHỆ AN 만료됨 26/2018/QĐ-UBND Quyết định số 26/2018/QĐ-UBND Sửa đổi Điều 4 Quy định chức năng, nhiệm vụ, quyền hạn và cơ cấu tổ chức của Sở Khoa học và Công nghệ, ban hành kèm theo Quyết định số 03/2016/QĐ-UBND ngày 15/01/2016 của Ủy ban nhân dân tỉnh Yên Bái 만료됨 29/2026/QĐ-UBND Quyết định số 29/2026/QĐ-UBND Ban hành quy định khu vực, địa điểm đổ thải, nhận chìm ở biển đối với vật chất nạo vét từ hệ thống giao thông đường thủy nội địa và đường biển; tuyến đường, thời gian vận chuyển chất thải rắn công nghiệp thông thường phải xử lý và chất thải nguy hại trên địa bàn tỉnh Đồng Tháp 발효 중 59/2025/QĐ-UBND Quyết định số 59/2025/QĐ-UBND Ban hành Quy định về sử dụng xe mô tô, xe gắn máy, xe thô sơ để kinh doanh vận chuyển hành khách, hàng hóa trên địa bàn tỉnh Quảng Ngãi 발효 중 36/2023/QĐ-UBND Quyết định số 36/2023/QĐ-UBND Phân cấp thẩm quyền cho các sở, ban, ngành, đoàn thể cấp tỉnh và UBND các huyện, thành phố ban hành tiêu chuẩn, định mức sử dụng máy móc, thiết bị chuyên dùng của các đơn vị thuộc phạm vi quản lý 만료됨 76/2024/QĐ-UBND Quyết định số 76/2024/QĐ-UBND Quy định điều kiện, tiêu chí, quy mô, tỷ lệ để tách khu đất thành dự án độc lập trên địa bàn tỉnh Cà Mau 발효 중 03/2021/QĐ-UBND Quyết định số 03/2021/QĐ-UBND Quy định chức năng, nhiệm vụ, quyền hạn và cơ cấu tổ chức của Đài Phát thanh và Truyền hình tỉnh Ninh Thuận 발효 중 50/2024/QĐ-UBND Quyết định số 50/2024/QĐ-UBND Ban hành Quy chế theo dõi, đôn đốc, kiểm tra việc thực hiện nhiệm vụdo Ủy ban nhân dân tỉnh, Chủ tịch Ủy ban nhân dân tỉnh giao trên địa bàn tỉnh Bắc Giang 발효 중 29/2021/QĐ-UBND Quyết định số 29/2021/QĐ-UBND Ban hành Quy chế phối hợp giải quyết việc đình công không đúng trình tự, thủ tục do pháp luật quy định trên địa bàn tỉnh Nghệ An 발효 중 28/2020/QĐ-UBND Quyết định số 28/2020/QĐ-UBND Quy định giá dịch vụ khám bệnh, chữa bệnh không thuộc phạm vi thanh toán của Quỹ bảo hiểm y tế trong các cơ sở khám bệnh, chữa bệnh của Nhà nước trên địa bàn tỉnh Ninh Thuận. 발효 중 38/2024/QĐ-UBND Quyết định số 38/2024/QĐ-UBND Quy chế phối hợp cung cấp thông tin về nhà ở trên địa bàn tỉnh Bạc Liêu 발효 중 10/2025/QĐ-UBND Quyết định số 10/2025/QĐ-UBND Ban hành Quy định chức năng, nhiệm vụ, quyền hạn và cơ cấu tổ chức của Sở Tư pháp tỉnh Quảng Trị 발효 중 33/2023/QĐ-UBND Quyết định số 33/2023/QĐ-UBND Quy định giá thóc làm căn cứ thu thuế sử dụng đất nông nghiệp trên địa bàn tỉnh Thái Nguyên 만료됨 07/2022/QĐ-UBND Quyết định số 07/2022/QĐ-UBND Ban hành Quy chế về tổ chức và hoạt động của Thanh tra Huyện thuộc Ủy ban nhân dân huyện Nhà Bè 발효 중 17/2021/QĐ-UBND Quyết định số 17/2021/QĐ-UBND Quy định việc quản lý hoạt động của xe ô tô vận tải trung chuyển hành khách trên địa bàn tỉnh Kiên Giang 만료됨 11/2023/QĐ-UBND Quyết định số 11/2023/QĐ-UBND Ban hành Quy định về phân công trách nhiệm của các cơ quan, đơn vị trong việc thực hiện chức năng quản lý nhà nước về an toàn đập, hồ chứa nước do tỉnh Lào Cai quản lý 발효 중 55/2021/QĐ-UBND Quyết định số 55/2021/QĐ-UBND Ban hành Quy định về quản lý và sử dụng mạng thông tin vô tuyến điện dùng riêng phục vụ công tác phòng, chống thiên tai và tìm kiếm cứu nạn trên địa bàn tỉnh Tiền Giang 만료됨 48/2024/QĐ-UBND Quyết định số 48/2024/QĐ-UBND Ban hành Bảng giá tính thuế tài nguyên trên địa bàn tỉnh Bà Rịa – Vũng Tàu năm 2025 만료됨 35/2021/QĐ-UBND QUYẾT ĐỊNH SỐ 35/2021/QĐ-UBND BAN HÀNH QUY CHẾ QUẢN LÝ, VẬN HÀNH VÀ SỬ DỤNG HỆ THỐNG HỘI NGHỊ TRUYỀN HÌNH TRỰC TUYẾN TRÊN ĐỊA BÀN TỈNH THANH HÓA 발효 중 39/2024/QĐ-UBND Quyết định số 39/2024/QĐ-UBND Sửa đổi, bổ sung Quyết định số 03/2020/QĐ-UBND ngày 13 tháng 01 năm 2020 của Ủy ban nhân dân tỉnh ban hành Quy định Bảng giá đất giai đoạn 2020 – 2024 trên địa bàn tỉnh Kiên Giang 만료됨 05/2017/QĐ-TTg Quyết định số 05/2017/QĐ-TTg Ban hành quy định về hệ thống phương án ứng cứu khẩn cấp bảo đảm an toàn thông tin mạng quốc gia 발효 중

문서를 클릭하면 열립니다. 빨간 테두리=효력을 변경하는 관계.